156-315.81.20 Threat Prevention and SandBlast Practice Question
A Check Point administrator wants to ensure that files downloaded from the internet are inspected by Threat Emulation before reaching the user. Which blade must be enabled in the Threat Prevention policy to achieve this?
⚠ Common exam trap
The trap here is assuming that Antivirus or IPS can provide sandboxing, but only Threat Emulation offers that capability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Threat Emulation
Threat Emulation is the blade that sends files to a sandbox for behavioral analysis. It detects malicious files by executing them in a safe environment. Enabling it in the Threat Prevention policy ensures files are inspected before reaching users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Antivirus
Why it's wrong here
Antivirus scans files against signatures but does not provide sandboxing or behavior analysis. While it can block known threats, it cannot detect zero-day or evasive malware that Threat Emulation catches. Thus, it does not fulfill the requirement of inspecting files in a sandbox.
- ✓
Threat Emulation
Why this is correct
Threat Emulation inspects files in a sandbox environment to detect malicious behavior. Enabling it ensures files are analyzed before delivery. This blade is specifically designed for file inspection and is the correct choice for this requirement.
- ✗
Threat Extraction
Why it's wrong here
Threat Extraction sanitizes files by removing active content, but it does not emulate or sandbox them. It is useful for neutralizing potential threats in documents, but it does not inspect files for malicious behavior in a sandbox environment like Threat Emulation does.
- ✗
IPS
Why it's wrong here
IPS inspects network traffic for malicious patterns but does not analyze files in a sandbox. It cannot detect file-based threats that require execution to reveal malicious behavior. Therefore, it is not the correct blade for file emulation.
About these practice questions
One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.